Vulnerability index

Browse CVEs

284 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Memory Buffer Bounds ErrorCWE-119 × clear
Debian Linux MEDIUM 6.8
CVE-2015-8036

Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial o…

Fix: 1.3.14 / 2.1.2+
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 6.8
CVE-2015-6031

Buffer overflow in the IGDstartelt function in igd_desc_parse.c in the MiniUPnP client (aka MiniUPnPc) before 1.9.20150917 allows remote UPNP servers…

Fix: after 1.9
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 6.8
CVE-2015-5291

Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote …

Fix: 1.2.17 / 1.3.14+
Fix from $1,600 2015-11-02
Debian Linux MEDIUM 6.8
CVE-2015-1781EPSS 5%

Buffer overflow in the gethostbyname_r and other unspecified NSS functions in the GNU C Library (aka glibc or libc6) before 2.22 allows context-depen…

Fix: after 2.21
Fix from $1,600 2015-09-28
Debian Linux MEDIUM 5.0
CVE-2015-3281

The buffer_slow_realign function in HAProxy 1.5.x before 1.5.14 and 1.6-dev does not properly realign a buffer that is used for pending outgoing data…

Patch available
Fix from $1,600 2015-07-06
Debian Linux HIGH 7.5
CVE-2015-1257

platform/graphics/filters/FEColorMatrix.cpp in the SVG implementation in Blink, as used in Google Chrome before 43.0.2357.65, does not properly handl…

Fix: after 42.0.2311.152
Fix from $1,950 2015-05-20
Debian Linux MEDIUM 5.0
CVE-2015-1246

Blink, as used in Google Chrome before 42.0.2311.90, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vector…

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Debian Linux MEDIUM 5.0
CVE-2015-1240

gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of …

Fix: after 42.0.2311.60
Fix from $1,600 2015-04-19
Debian Linux MEDIUM 6.5
CVE-2015-1821

Heap-based buffer overflow in chrony before 1.31.1 allows remote authenticated users to cause a denial of service (chronyd crash) or possibly execute…

Fix: after 1.31
Fix from $1,600 2015-04-16
Debian Linux HIGH 10.0
CVE-2015-2788

Multiple stack-based buffer overflows in the ib_fill_isqlda function in dbdimp.c in DBD-Firebird before 1.19 allow remote attackers to have unspecifi…

Fix: after 1.18
Fix from $1,950 2015-04-14
Debian Linux HIGH 7.5
CVE-2015-2782EPSS 6%

Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code v…

Mitigation only
Fix from $1,950 2015-04-08
Debian Linux HIGH 7.5
CVE-2015-0838

Buffer overflow in the C implementation of the apply_delta function in _pack.c in Dulwich before 0.9.9 allows remote attackers to execute arbitrary c…

Fix: after 0.9.8
Fix from $1,950 2015-03-31
Cifs Utils HIGH 10.0
CVE-2014-2830EPSS 6%

Stack-based buffer overflow in cifskey.c or cifscreds.c in cifs-utils before 6.4, as used in pam_cifscreds, allows remote attackers to have unspecifi…

Fix: after 6.3
Fix from $1,950 2015-03-31
Debian Linux MEDIUM 5.8
CVE-2014-9672

Array index error in the parse_fond function in base/ftmac.c in FreeType before 2.5.4 allows remote attackers to cause a denial of service (out-of-bo…

Fix: after 2.5.3
Fix from $1,600 2015-02-08
Debian Linux MEDIUM 6.8
CVE-2014-9667

sfnt/ttload.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting the values, which allows remote attackers to caus…

No fix yet
Fix from $1,600 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9663EPSS 5%

The tt_cmap4_validate function in sfnt/ttcmap.c in FreeType before 2.5.4 validates a certain length field before that field's value is completely cal…

Patch available
Fix from $1,950 2015-02-08
Debian Linux HIGH 7.5
CVE-2014-9662

cff/cf2ft.c in FreeType before 2.5.4 does not validate the return values of point-allocation functions, which allows remote attackers to cause a deni…

Fix: after 2.5.3
Fix from $1,950 2015-02-08
Debian Linux MEDIUM 6.8
CVE-2014-8158EPSS 14%

Multiple stack-based buffer overflows in jpc_qmfb.c in JasPer 1.900.1 and earlier allow remote attackers to cause a denial of service (crash) or poss…

Fix: after 1.900.1
Fix from $1,600 2015-01-26
Debian Linux HIGH 7.5
CVE-2014-8145EPSS 8%

Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV f…

Fix: after 14.4.1
Fix from $1,950 2014-12-31
Debian Linux MEDIUM 6.5
CVE-2014-8102

The SProcXFixesSelectSelectionInput function in the XFixes extension in X.Org X Window System (aka X11 or X) X11R6.8.0 and X.Org Server (aka xserver …

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8098EPSS 5%

The GLX extension in XFree86 4.0, X.Org X Window System (aka X11 or X) X11R6.7, and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows r…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8096

The SProcXCMiscGetXIDList function in the XC-MISC extension in X.Org X Window System (aka X11 or X) X11R6.0 and X.Org Server (aka xserver and xorg-se…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 6.5
CVE-2014-8095

The XInput extension in X.Org X Window System (aka X11 or X) X11R4 and X.Org Server (aka xserver and xorg-server) before 1.16.3 allows remote authent…

Fix: after 1.16.2.99.901
Fix from $1,600 2014-12-10
Debian Linux MEDIUM 5.0
CVE-2014-9116EPSS 10%

The write_one_header function in mutt 1.5.23 does not properly handle newline characters at the beginning of a header, which allows remote attackers …

No fix yet
Fix from $1,600 2014-12-02
Debian Linux MEDIUM 5.0
CVE-2014-9112EPSS 7%

Heap-based buffer overflow in the process_copy_in function in GNU Cpio 2.11 allows remote attackers to cause a denial of service via a large block va…

No fix yet
Fix from $1,600 2014-12-02
Advanced Package Tool MEDIUM 6.8
CVE-2014-6273

Buffer overflow in the HTTP transport code in apt-get in APT 1.0.1 and earlier allows man-in-the-middle attackers to cause a denial of service (crash…

Fix: after 1.0.1
Fix from $1,600 2014-09-30
Debian Linux MEDIUM 5.0
CVE-2014-4342EPSS 7%

MIT Kerberos 5 (aka krb5) 1.7.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read or NULL pointer d…

Patch available
Fix from $1,600 2014-07-20
Xbuffy MEDIUM 6.8
CVE-2014-0469

Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execute arbitrary code via the sub…

Fix: after 3.3.bl.3.dfsg-8
Fix from $1,600 2014-05-05
Ppthtml MEDIUM 6.8
CVE-2013-4565

Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and …

Fix: after 0.5.1
Fix from $1,600 2014-04-25
Debian Linux MEDIUM 5.0
CVE-2014-0159

Buffer overflow in the GetStatistics64 remote procedure call (RPC) in OpenAFS 1.4.8 before 1.6.7 allows remote attackers to cause a denial of service…

Mitigation only
Fix from $1,600 2014-04-14